nodejs lack-of-QA comes back to bite them in the ass yet again. wasn't the first time nor will it be the last time, ditch this bullshit.
Explain to me how "QA" prevents a malicious package from transitively including another one and taking advantage of typo squatting.
To publish an Android app, I need to verify my name by paying Google some money ($25?) and my code has to pass some automated checks.
It seems like anyone can publish just about anything anonymously on npm. That model has upsides, but it's not exactly state-of-the art in terms of QA (though you could argue whether QA is the right term here).